CVE-2020-11081
CVE-2020-11081 is a medium-severity vulnerability in Linuxfoundation Osquery with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-426.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- CVSS v2: 4.4
- EPSS exploit prediction: 1% (46th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-426
- Affected product: Linuxfoundation Osquery
- Published:
- Last modified:
Description
osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables local escalation. This is fixed in version 4.4.0.
Frequently asked questions
- What is CVE-2020-11081?
- osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables local escalation. This is fixed in version 4.4.0.
- How severe is CVE-2020-11081?
- CVE-2020-11081 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over local access with high attack complexity, requires low privileges and user interaction. Impact on confidentiality is none, integrity high, and availability none.
- Is CVE-2020-11081 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (46th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2020-11081?
- CVE-2020-11081 affects Linuxfoundation Osquery. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2020-11081?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2020-11081 published?
- CVE-2020-11081 was published on 2020-07-10 and last updated on 2026-06-17.
References
- https://github.com/osquery/osquery/commit/4d4957f12a6aa0becc9d01d9f97061e1e3d809c5
- https://github.com/osquery/osquery/issues/6426
- https://github.com/osquery/osquery/pull/6433
- https://github.com/osquery/osquery/releases/tag/4.4.0
- https://github.com/osquery/osquery/security/advisories/GHSA-2xwp-8fv7-c5pm
Affected products (1)
- cpe:2.3:a:linuxfoundation:osquery:*:*:*:*:*:*:*:*
More vulnerabilities in Linuxfoundation Osquery
- CVE-2020-1887 — Critical (CVSS 9.1): Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker…
- CVE-2019-3567 — High (CVSS 8.1): In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard…
- CVE-2018-6336 — High (CVSS 7.8): An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing…
- CVE-2020-26273 — Medium (CVSS 5.2): osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. In osquery before…
All CVEs affecting Linuxfoundation Osquery →
Other CWE-426 (Untrusted Search Path) vulnerabilities
- CVE-2026-78155 — Critical (CVSS 9.9): privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator…
- CVE-2026-74872 — Critical (CVSS 9.8): openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash…
- CVE-2026-45772 — Critical (CVSS 9.8): Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14,…
- CVE-2025-26155 — Critical (CVSS 9.8): NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path…
- CVE-2024-53866 — Critical (CVSS 9.8): The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one…
- CVE-2024-38462 — Critical (CVSS 9.8): iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the…
Browse all CWE-426 (Untrusted Search Path) vulnerabilities →